Release_iOS-17-0_macOS-14-0

This commit is contained in:
Cyrus Daboo
2023-09-14 17:37:41 -04:00
parent 5a8fb0deb2
commit 72c2a0a69f
254 changed files with 6787 additions and 969 deletions
+4
View File
@@ -5,6 +5,7 @@ payload:
supportedOS:
iOS:
introduced: '4.0'
multiple: false
supervised: false
allowmanualinstall: true
sharedipad:
@@ -15,6 +16,7 @@ payload:
mode: allowed
macOS:
introduced: '10.7'
multiple: false
devicechannel: true
userchannel: true
requiresdep: false
@@ -24,10 +26,12 @@ payload:
mode: allowed
tvOS:
introduced: '5.0'
multiple: false
supervised: false
allowmanualinstall: true
watchOS:
introduced: '1.0'
multiple: false
allowmanualinstall: true
payloadkeys:
- key: PayloadIdentifier
+1
View File
@@ -5,6 +5,7 @@ payload:
supportedOS:
macOS:
introduced: '10.7'
multiple: false
devicechannel: true
userchannel: true
requiresdep: false
+4 -4
View File
@@ -5,6 +5,7 @@ payload:
supportedOS:
iOS:
introduced: '4.0'
multiple: false
supervised: false
allowmanualinstall: true
sharedipad:
@@ -15,6 +16,7 @@ payload:
mode: allowed
macOS:
introduced: '10.7'
multiple: false
devicechannel: true
userchannel: true
requiresdep: false
@@ -24,10 +26,12 @@ payload:
mode: allowed
tvOS:
introduced: '5.0'
multiple: false
supervised: false
allowmanualinstall: true
watchOS:
introduced: '1.0'
multiple: false
allowmanualinstall: true
payloadkeys:
- key: PayloadIdentifier
@@ -104,10 +108,6 @@ payloadkeys:
supervised: true
userenrollment:
mode: forbidden
macOS:
supervised: true
userenrollment:
mode: forbidden
tvOS:
supervised: true
watchOS:
@@ -5,6 +5,7 @@ payload:
supportedOS:
macOS:
introduced: '10.7'
multiple: true
devicechannel: true
userchannel: true
requiresdep: false
+1
View File
@@ -7,6 +7,7 @@ payload:
introduced: '10.7'
deprecated: '10.13'
removed: '10.14'
multiple: true
devicechannel: false
userchannel: true
requiresdep: false
@@ -5,6 +5,7 @@ payload:
supportedOS:
macOS:
introduced: 10.13.4
multiple: false
devicechannel: true
userchannel: false
requiresdep: false
+1
View File
@@ -5,6 +5,7 @@ payload:
supportedOS:
macOS:
introduced: '10.7'
multiple: false
devicechannel: true
userchannel: true
requiresdep: false
@@ -5,6 +5,7 @@ payload:
supportedOS:
macOS:
introduced: '10.8'
multiple: true
devicechannel: true
userchannel: false
requiresdep: false
@@ -5,6 +5,7 @@ payload:
supportedOS:
macOS:
introduced: '10.7'
multiple: false
devicechannel: true
userchannel: true
requiresdep: false
@@ -5,6 +5,7 @@ payload:
supportedOS:
macOS:
introduced: '10.7'
multiple: true
devicechannel: true
userchannel: false
requiresdep: false
@@ -5,6 +5,7 @@ payload:
supportedOS:
macOS:
introduced: '10.7'
multiple: true
devicechannel: true
userchannel: false
requiresdep: false
@@ -5,6 +5,7 @@ payload:
supportedOS:
macOS:
introduced: '10.7'
multiple: false
devicechannel: true
userchannel: false
requiresdep: false
@@ -5,6 +5,7 @@ payload:
supportedOS:
macOS:
introduced: '10.7'
multiple: false
devicechannel: true
userchannel: true
requiresdep: false
@@ -5,6 +5,7 @@ payload:
supportedOS:
macOS:
introduced: 10.12.4
multiple: false
devicechannel: true
userchannel: false
requiresdep: false
+4 -3
View File
@@ -5,6 +5,7 @@ payload:
supportedOS:
macOS:
introduced: '10.9'
multiple: true
devicechannel: true
userchannel: false
requiresdep: false
@@ -20,7 +21,7 @@ payloadkeys:
type: <boolean>
presence: optional
default: false
content: If YES, requires administrator authorization to enable IBSS.
content: If 'true', requires administrator authorization to enable IBSS.
- key: RequireAdminForAirPortNetworkChange
supportedOS:
macOS:
@@ -28,7 +29,7 @@ payloadkeys:
type: <boolean>
presence: optional
default: false
content: If YES, requires administrator authorization for network changes.
content: If 'true', requires administrator authorization for network changes.
- key: RequireAdminToTurnAirPortOnOff
supportedOS:
macOS:
@@ -36,4 +37,4 @@ payloadkeys:
type: <boolean>
presence: optional
default: false
content: If YES, requires administrator authorization to turn Wi-Fi on or off.
content: If 'true', requires administrator authorization to turn Wi-Fi on or off.
@@ -5,6 +5,7 @@ payload:
supportedOS:
macOS:
introduced: '10.9'
multiple: false
devicechannel: true
userchannel: false
requiresdep: false
@@ -93,3 +94,15 @@ payloadkeys:
presence: optional
default: false
content: If 'true', prevents requests for enabling FileVault at user logout time.
- key: ForceEnableInSetupAssistant
supportedOS:
macOS:
introduced: '14.0'
requiresdep: true
allowmanualinstall: false
type: <boolean>
presence: optional
default: false
content: |-
If 'true', and this payload is installed after enrolling with MDM in Setup Assistant, it requests Setup Assistant to enable FileVault at setup time.
To use this, enable the Await Device Configured DEP configuration option, send this profile with this key set, before sending the DeviceConfigured command. An admin SecureToken user is required, otherwise the FileVault pane does not appear.
+2 -1
View File
@@ -4,6 +4,7 @@ payload:
supportedOS:
macOS:
introduced: '10.7'
multiple: false
devicechannel: true
userchannel: false
requiresdep: false
@@ -21,7 +22,7 @@ payloadkeys:
type: <boolean>
presence: optional
default: false
content: If true, backs up only the startup volume by default.
content: If 'true', backs up only the startup volume by default.
- key: BackupDestURL
type: <string>
presence: required
@@ -5,6 +5,7 @@ payload:
supportedOS:
macOS:
introduced: '10.7'
multiple: true
devicechannel: true
userchannel: true
requiresdep: false
+1
View File
@@ -5,6 +5,7 @@ payload:
supportedOS:
macOS:
introduced: '10.13'
multiple: true
devicechannel: true
userchannel: true
requiresdep: false
@@ -5,6 +5,7 @@ payload:
supportedOS:
iOS:
introduced: '14.0'
multiple: false
supervised: true
allowmanualinstall: true
sharedipad:
@@ -15,6 +16,7 @@ payload:
mode: forbidden
macOS:
introduced: '10.12'
multiple: false
devicechannel: true
userchannel: true
requiresdep: false
@@ -32,7 +34,7 @@ payloadkeys:
type: <boolean>
presence: optional
default: false
content: If 'true', skips the Apple ID setup window.
content: If 'true', the system skips the Apple ID setup window.
- key: SkipSiriSetup
supportedOS:
iOS:
@@ -40,7 +42,7 @@ payloadkeys:
type: <boolean>
presence: optional
default: false
content: If 'true', skips the Siri setup window.
content: If 'true', the system skips the Siri setup window.
- key: SkipPrivacySetup
supportedOS:
iOS:
@@ -50,7 +52,7 @@ payloadkeys:
type: <boolean>
presence: optional
default: false
content: If 'true', skips the Privacy consent window.
content: If 'true', the system skips the Privacy consent window.
- key: SkipiCloudStorageSetup
supportedOS:
iOS:
@@ -60,7 +62,7 @@ payloadkeys:
type: <boolean>
presence: optional
default: false
content: If 'true', skips the iCloud Storage window.
content: If 'true', the system skips the iCloud Storage window.
- key: SkipTrueTone
supportedOS:
iOS:
@@ -70,7 +72,7 @@ payloadkeys:
type: <boolean>
presence: optional
default: false
content: If 'true', skips the True Tone Display window.
content: If 'true', the system skips the True Tone Display window.
- key: SkipAppearance
supportedOS:
iOS:
@@ -80,7 +82,7 @@ payloadkeys:
type: <boolean>
presence: optional
default: false
content: If 'true', skips the Choose Your Look window.
content: If 'true', the system skips the Choose Your Look window.
- key: SkipTouchIDSetup
supportedOS:
iOS:
@@ -90,7 +92,7 @@ payloadkeys:
type: <boolean>
presence: optional
default: false
content: If true, skips the Touch ID setup window.
content: If 'true', the system skips the Touch ID setup window.
- key: SkipScreenTime
supportedOS:
iOS:
@@ -100,7 +102,7 @@ payloadkeys:
type: <boolean>
presence: optional
default: false
content: If true, skips the Screen Time window.
content: If 'true', the system skips the Screen Time window.
- key: SkipAccessibility
supportedOS:
iOS:
@@ -110,7 +112,7 @@ payloadkeys:
type: <boolean>
presence: optional
default: false
content: Skips Accessibility window
content: If 'true', the system skips the Accessibility window.
- key: SkipSetupItems
supportedOS:
iOS:
@@ -134,4 +136,4 @@ payloadkeys:
type: <boolean>
presence: optional
default: false
content: Skips Unlock With Apple Watch window
content: If 'true', the system skips the Unlock With Apple Watch window.
@@ -6,6 +6,7 @@ payload:
macOS:
introduced: '10.9'
deprecated: '10.12'
multiple: false
devicechannel: true
userchannel: true
requiresdep: false
@@ -5,6 +5,7 @@ payload:
supportedOS:
macOS:
introduced: '10.7'
multiple: false
devicechannel: true
userchannel: false
requiresdep: false
@@ -4,6 +4,7 @@ payload:
supportedOS:
macOS:
introduced: '10.7'
multiple: false
devicechannel: true
userchannel: false
requiresdep: false
@@ -5,6 +5,7 @@ payload:
supportedOS:
macOS:
introduced: '10.14'
multiple: true
devicechannel: true
userchannel: false
requiresdep: false
@@ -46,7 +47,7 @@ payloadkeys:
- key: CodeRequirement
type: <string>
presence: required
content: Obtained via the command ''codesign display -r -''.
content: Obtained via the command ''codesign -display -r -''.
- key: StaticCode
type: <boolean>
presence: optional
@@ -269,3 +270,12 @@ payloadkeys:
13 and later.
subkeytype: Identity
subkeys: *id001
- key: SystemPolicyAppData
supportedOS:
macOS:
introduced: '14.0'
type: <array>
presence: optional
content: Allows the application to access data of other apps.
subkeytype: Identity
subkeys: *id001
@@ -5,6 +5,7 @@ payload:
supportedOS:
tvOS:
introduced: '11.0'
multiple: false
supervised: false
allowmanualinstall: true
content: Manages the AirPlay Security settings on Apple TV (Settings > AirPlay >
+2
View File
@@ -5,6 +5,7 @@ payload:
supportedOS:
iOS:
introduced: '7.0'
multiple: true
supervised: false
allowmanualinstall: true
sharedipad:
@@ -15,6 +16,7 @@ payload:
mode: allowed
macOS:
introduced: '10.10'
multiple: true
devicechannel: true
userchannel: true
requiresdep: false
+2
View File
@@ -5,6 +5,7 @@ payload:
supportedOS:
iOS:
introduced: '7.0'
multiple: true
supervised: false
allowmanualinstall: true
sharedipad:
@@ -15,6 +16,7 @@ payload:
mode: allowed
macOS:
introduced: '10.10'
multiple: true
devicechannel: true
userchannel: true
requiresdep: false
+1
View File
@@ -6,6 +6,7 @@ payload:
iOS:
introduced: '4.0'
deprecated: '7.0'
multiple: false
supervised: false
allowmanualinstall: true
sharedipad:
+2
View File
@@ -5,6 +5,7 @@ payload:
supportedOS:
iOS:
introduced: '6.0'
multiple: false
supervised: true
allowmanualinstall: true
sharedipad:
@@ -15,6 +16,7 @@ payload:
mode: forbidden
tvOS:
introduced: '10.2'
multiple: false
supervised: true
allowmanualinstall: true
payloadkeys:
@@ -5,6 +5,7 @@ payload:
supportedOS:
macOS:
introduced: '10.7'
multiple: true
devicechannel: true
userchannel: true
requiresdep: false
File diff suppressed because it is too large Load Diff
+1
View File
@@ -5,6 +5,7 @@ payload:
supportedOS:
macOS:
introduced: '10.9'
multiple: false
devicechannel: true
userchannel: true
requiresdep: false
+1
View File
@@ -5,6 +5,7 @@ payload:
supportedOS:
macOS:
introduced: 10.13.4
multiple: false
devicechannel: true
userchannel: false
requiresdep: false
@@ -6,6 +6,7 @@ payload:
supportedOS:
macOS:
introduced: '10.15'
multiple: true
devicechannel: true
userchannel: true
requiresdep: false
@@ -6,6 +6,7 @@ payload:
supportedOS:
iOS:
introduced: '4.0'
multiple: true
supervised: false
allowmanualinstall: true
sharedipad:
@@ -16,6 +17,7 @@ payload:
mode: allowed
macOS:
introduced: '10.7'
multiple: true
devicechannel: false
userchannel: true
requiresdep: false
@@ -6,6 +6,7 @@ payload:
supportedOS:
iOS:
introduced: '4.0'
multiple: true
supervised: false
allowmanualinstall: true
sharedipad:
@@ -16,6 +17,7 @@ payload:
mode: allowed
macOS:
introduced: '10.7'
multiple: true
devicechannel: false
userchannel: true
requiresdep: false
+2
View File
@@ -5,6 +5,7 @@ payload:
supportedOS:
iOS:
introduced: '7.0'
multiple: false
supervised: false
allowmanualinstall: true
sharedipad:
@@ -15,6 +16,7 @@ payload:
mode: forbidden
watchOS:
introduced: '3.2'
multiple: false
allowmanualinstall: true
content: |-
This payload cannot be installed if an APN payload is already installed.
@@ -0,0 +1,73 @@
title: Cellular Private Network
description: Cellular Private Network Settings and Device Configuration
payload:
payloadtype: com.apple.cellularprivatenetwork.managed
supportedOS:
iOS:
introduced: '17.0'
multiple: false
supervised: false
allowmanualinstall: true
sharedipad:
mode: allowed
devicechannel: true
userchannel: false
userenrollment:
mode: allowed
content: Payload can be used to provide device info on private network deployments
including geographical location, preference over wifi, and network deployment
type.
payloadkeys:
- key: Geofences
type: <array>
presence: optional
content: A list of up to 1000 geofences for private networks. Geofencing is only
used on iPhone.
subkeys:
- key: GeofenceItem
type: <dictionary>
subkeys:
- key: Longitude
type: <real>
presence: required
range:
min: -180.0
max: 180.0
content: The longitude of the geofence.
- key: Latitude
type: <real>
presence: required
range:
min: -90.0
max: 90.0
content: The latitude of the geofence.
- key: Radius
type: <real>
presence: required
range:
min: 100.0
max: 6500.0
content: Specifies the radius of the geofence in meters. Set this value slightly
greater than the private cellular network coverage area.
- key: GeofenceId
type: <string>
presence: required
content: A geofence identifier that's unique within a list of geofences.
- key: DataSetName
type: <string>
presence: required
content: The name of the private network configuration data set.
- key: VersionNumber
type: <string>
presence: required
content: The version number of this dataset that the system uses to track updates.
- key: CellularDataPreferred
type: <boolean>
presence: optional
default: false
content: Set to 'true' to prefer this private network over Wi-Fi.
- key: EnableNRStandalone
type: <boolean>
presence: optional
default: false
content: Set to 'true' if this private network is NR Standalone.
@@ -6,6 +6,7 @@ payload:
supportedOS:
tvOS:
introduced: '10.2'
multiple: false
supervised: true
allowmanualinstall: true
content: Configures an Apple TV to enter Conference Room Display mode, and restrictions
@@ -4,6 +4,7 @@ payload:
supportedOS:
macOS:
introduced: '10.7'
multiple: false
devicechannel: true
userchannel: true
requiresdep: false
+1
View File
@@ -7,6 +7,7 @@ payload:
introduced: '10.7'
deprecated: '10.15'
removed: '10.15'
multiple: false
devicechannel: true
userchannel: true
requiresdep: false
+51
View File
@@ -0,0 +1,51 @@
title: Declarations
description: Declarations
payload:
payloadtype: com.apple.declarations
supportedOS:
iOS:
introduced: '17.0'
multiple: true
supervised: false
allowmanualinstall: true
sharedipad:
mode: forbidden
userenrollment:
mode: forbidden
macOS:
introduced: '14.0'
multiple: true
devicechannel: true
userchannel: true
requiresdep: false
userapprovedmdm: false
allowmanualinstall: true
userenrollment:
mode: forbidden
tvOS:
introduced: '17.0'
multiple: true
supervised: false
allowmanualinstall: true
watchOS:
introduced: '10.0'
multiple: true
supervised: false
allowmanualinstall: true
content: This profile applies a set of declarations to the device via the Settings
app. This allows manual installations of declarations in cases where an MDM enrollment
is not present. This profile can only be manually installed, and cannot be installed
via an MDM server.
payloadkeys:
- key: Declarations
title: Declarations
type: <array>
presence: required
content: The set of declarations to apply. The items in this array are Base64-encoded
data representations of the declaration JSON data.
subkeys:
- key: DeclarationsItem
title: Declarations Content Item
type: <data>
presence: required
content: An item in the declarations list
+1
View File
@@ -5,6 +5,7 @@ payload:
supportedOS:
macOS:
introduced: '10.10'
multiple: false
devicechannel: true
userchannel: true
requiresdep: false
@@ -5,6 +5,7 @@ payload:
supportedOS:
iOS:
introduced: '11.0'
multiple: false
supervised: false
allowmanualinstall: false
sharedipad:
@@ -15,6 +16,7 @@ payload:
mode: allowed
macOS:
introduced: '10.15'
multiple: false
devicechannel: true
userchannel: false
requiresdep: false
@@ -5,6 +5,7 @@ payload:
supportedOS:
iOS:
introduced: '14.0'
multiple: true
supervised: false
allowmanualinstall: true
sharedipad:
@@ -15,6 +16,7 @@ payload:
mode: forbidden
macOS:
introduced: '11.0'
multiple: true
devicechannel: true
userchannel: false
requiresdep: false
@@ -185,3 +187,15 @@ payloadkeys:
default: false
content: If 'true', prohibits users from disabling DNS settings. This key is only
available on supervised devices.
- key: PayloadCertificateUUID
title: Certificate UUID
supportedOS:
iOS:
introduced: '16.0'
macOS:
introduced: '13.0'
type: <string>
presence: optional
format: ^[0-9A-Za-z]{8}-[0-9A-Za-z]{4}-[0-9A-Za-z]{4}-[0-9A-Za-z]{4}-[0-9A-Za-z]{12}$
content: The UUID that points to an identity certificate payload. The system uses
this identity to authenticate the user to the DNS resolver.
+1
View File
@@ -5,6 +5,7 @@ payload:
supportedOS:
macOS:
introduced: '10.7'
multiple: false
devicechannel: true
userchannel: true
requiresdep: false
+2
View File
@@ -5,6 +5,7 @@ payload:
supportedOS:
iOS:
introduced: '8.0'
multiple: false
supervised: false
allowmanualinstall: true
sharedipad:
@@ -15,6 +16,7 @@ payload:
mode: forbidden
macOS:
introduced: '10.10'
multiple: false
devicechannel: true
userchannel: true
requiresdep: false
+1
View File
@@ -5,6 +5,7 @@ payload:
supportedOS:
iOS:
introduced: '4.0'
multiple: true
supervised: false
allowmanualinstall: true
sharedipad:
+2
View File
@@ -5,6 +5,7 @@ payload:
supportedOS:
iOS:
introduced: '9.3'
multiple: false
supervised: false
allowmanualinstall: true
sharedipad:
@@ -15,6 +16,7 @@ payload:
mode: allowed
macOS:
introduced: '10.14'
multiple: false
devicechannel: false
userchannel: true
requiresdep: false
+1
View File
@@ -5,6 +5,7 @@ payload:
supportedOS:
macOS:
introduced: '10.7'
multiple: true
devicechannel: false
userchannel: true
requiresdep: false
@@ -5,6 +5,7 @@ payload:
supportedOS:
iOS:
introduced: '13.0'
multiple: true
supervised: false
allowmanualinstall: false
sharedipad:
@@ -15,6 +16,7 @@ payload:
mode: allowed
macOS:
introduced: '10.15'
multiple: true
devicechannel: true
userchannel: true
requiresdep: false
+129 -3
View File
@@ -5,6 +5,7 @@ payload:
supportedOS:
iOS:
introduced: '13.0'
multiple: true
supervised: false
allowmanualinstall: false
sharedipad:
@@ -15,6 +16,7 @@ payload:
mode: allowed
macOS:
introduced: '10.15'
multiple: true
devicechannel: true
userchannel: true
requiresdep: false
@@ -60,7 +62,7 @@ payloadkeys:
- key: ANY
type: <any>
presence: optional
content: Keys and values to be passed to the app extension.
content: Keys and values to pass to the app extension.
- key: URLs
type: <array>
presence: optional
@@ -123,6 +125,7 @@ payloadkeys:
introduced: n/a
macOS:
introduced: '13.0'
deprecated: '14.0'
type: <string>
presence: optional
rangelist:
@@ -130,7 +133,7 @@ payloadkeys:
- UserSecureEnclaveKey
content: |-
The Platform SSO authentication method the extension uses. Requires that the SSO Extension also supports the method.
Available in macOS 13 and later.
Available in macOS 13 and later and deprecated in macOS 14.
- key: RegistrationToken
supportedOS:
iOS:
@@ -140,5 +143,128 @@ payloadkeys:
type: <string>
presence: optional
content: |-
The token this device uses for registration with Platform SSO. Use it for silent registration with the Identity Provider. Requires that 'AuthenticationMethod' isn't empty.
The token this device uses for registration with Platform SSO. Use it for silent registration with the Identity Provider. Requires that 'PlatformSSO' 'AuthenticationMethod' isn't empty.
Available in macOS 13 and later.
- key: PlatformSSO
supportedOS:
iOS:
introduced: n/a
macOS:
introduced: '14.0'
type: <dictionary>
presence: optional
content: The dictionary to configure Platform SSO.
subkeys:
- key: AuthenticationMethod
type: <string>
presence: optional
rangelist:
- Password
- UserSecureEnclaveKey
- SmartCard
content: The Platform SSO authentication method to use with the extension. Requires
that the SSO Extension also support the method.
- key: UseSharedDeviceKeys
type: <boolean>
presence: optional
default: false
content: If 'true', the system uses the same signing and encryption keys for all
users.
- key: AccountDisplayName
type: <string>
presence: optional
content: The display name for the account in notifications and authentication
requests.
- key: LoginFrequency
type: <integer>
presence: optional
range:
min: 3600
default: 64800
content: The duration, in seconds, until the system requires a full login instead
of a refresh. The default value is 64,800 (18 hours). The minimum value is 3600
(1 hour).
- key: EnableCreateUserAtLogin
type: <boolean>
presence: optional
default: false
content: Enables creating new users at the login window with an 'AuthenticationMethod'
of either 'Password' or 'SmartCard'. Requires that 'UseSharedDeviceKeys' is
'true'.
- key: EnableAuthorization
type: <boolean>
presence: optional
default: false
content: Enables using identity provider accounts at authorization prompts. Requires
that 'UseSharedDeviceKeys' is 'true'. The system assigns groups using 'AdministratorGroups',
'AdditionalGroups', or 'AuthorizationGroups'.
- key: TokenToUserMapping
type: <dictionary>
presence: optional
content: The attribute mapping to use when creating new users or for authorization.
subkeys:
- key: AccountName
type: <string>
presence: optional
content: The claim name to use for the user's account name.
- key: FullName
type: <string>
presence: optional
content: The claim name to use for the user's full name.
- key: NewUserAuthorizationMode
type: <string>
presence: optional
rangelist:
- Standard
- Admin
- Groups
content: |-
The permission to apply to newly created accounts at login, which has the following values:
* 'Standard': The account is a standard user.
* 'Admin': The system adds the account to the local administrators group.
* 'Groups': The system assigns group to the account using 'AdministratorGroups', 'AdditionalGroups', or 'AuthorizationGroups'.
- key: UserAuthorizationMode
type: <string>
presence: optional
rangelist:
- Standard
- Admin
- Groups
content: |-
The permission to apply to an account each time the user authenticates, which has the following values:
* 'Standard': The account is a standard user.
* 'Admin': The system adds the account to the local administrators group.
* 'Groups': The system assigns group to the account using 'AdministratorGroups', 'AdditionalGroups', or 'AuthorizationGroups'.
- key: AdministratorGroups
type: <array>
presence: optional
content: The list of groups to use for administrator access. The system requests
membership during authentication.
subkeys:
- key: Group
type: <string>
presence: optional
content: The group name.
- key: AdditionalGroups
type: <array>
presence: optional
content: The list of created groups that don't have administrator access.
subkeys:
- key: Group
type: <string>
presence: optional
content: The group name.
- key: AuthorizationGroups
type: <dictionary>
presence: optional
content: The pairing of Authorization Rights to group names. The system updates
the Authorization Right to use the group when used.
subkeys:
- key: Authorization Right
type: <string>
presence: required
content: The Authorization Right to update.
- key: Group
type: <string>
presence: required
content: The group to use for the Authorization Right.
@@ -5,6 +5,7 @@ payload:
supportedOS:
macOS:
introduced: '10.7'
multiple: false
devicechannel: true
userchannel: true
requiresdep: false
@@ -5,6 +5,7 @@ payload:
supportedOS:
macOS:
introduced: '10.7'
multiple: false
devicechannel: true
userchannel: true
requiresdep: false
@@ -5,6 +5,7 @@ payload:
supportedOS:
macOS:
introduced: '11.0'
multiple: false
devicechannel: true
userchannel: true
requiresdep: false
+11 -10
View File
@@ -5,6 +5,7 @@ payload:
supportedOS:
macOS:
introduced: '10.7'
multiple: false
devicechannel: true
userchannel: true
requiresdep: false
@@ -17,7 +18,7 @@ payloadkeys:
type: <boolean>
presence: optional
default: false
content: If 'true', disables the Finder's burn support.
content: If 'true', the system disables the Finder's burn support.
- key: InterfaceLevel
supportedOS:
macOS:
@@ -27,44 +28,44 @@ payloadkeys:
rangelist:
- Simple
- Full
content: If Finder should operate in Simple or Full mode.
content: Specifies whether Finder should operate in Simple or Full mode.
- key: ProhibitConnectTo
type: <boolean>
presence: optional
default: false
content: If set to true, Connect to Server will be disabled.
content: If 'true', the system disables Connect to Server.
- key: ProhibitEject
type: <boolean>
presence: optional
default: false
content: If set to true, Eject will be disabled.
content: If 'true', the system disables Eject.
- key: ProhibitGoToFolder
type: <boolean>
presence: optional
default: false
content: If set to true, Go To Folder will be disabled.
content: If 'true', the system disables Go to Folder.
- key: ShowExternalHardDrivesOnDesktop
type: <boolean>
presence: optional
default: true
content: If set to false, external hard drives will not appear on the desktop.
content: If 'false', external hard drives don't appear on the Desktop.
- key: ShowHardDrivesOnDesktop
type: <boolean>
presence: optional
default: false
content: If set to false, internal hard drives will not appear on the desktop.
content: If 'false', internal hard drives don't appear on the Desktop.
- key: ShowMountedServersOnDesktop
type: <boolean>
presence: optional
default: false
content: If set to false, mounted file servers will not appear on the desktop.
content: If 'false', mounted file servers don't appear on the Desktop.
- key: ShowRemovableMediaOnDesktop
type: <boolean>
presence: optional
default: true
content: If set to false, removable media will not appear on the desktop.
content: If 'false', removable media items don't appear on the Desktop.
- key: WarnOnEmptyTrash
type: <boolean>
presence: optional
default: true
content: If set to false, user will not be warned before emptying the trash.
content: If 'false', the user isn't warned before emptying the trash.
@@ -5,6 +5,7 @@ payload:
supportedOS:
macOS:
introduced: '10.7'
multiple: false
devicechannel: true
userchannel: true
requiresdep: false
@@ -5,6 +5,7 @@ payload:
supportedOS:
macOS:
introduced: '10.7'
multiple: false
devicechannel: true
userchannel: true
requiresdep: false
+2
View File
@@ -5,6 +5,7 @@ payload:
supportedOS:
iOS:
introduced: '7.0'
multiple: true
supervised: false
allowmanualinstall: true
sharedipad:
@@ -13,6 +14,7 @@ payload:
mode: allowed
macOS:
introduced: '10.9'
multiple: true
devicechannel: true
userchannel: true
requiresdep: false
+1
View File
@@ -5,6 +5,7 @@ payload:
supportedOS:
macOS:
introduced: '10.9'
multiple: false
devicechannel: true
userchannel: true
requiresdep: false
@@ -3,8 +3,20 @@ description: ''
payload:
payloadtype: com.apple.globalethernet.managed
supportedOS:
iOS:
introduced: '17.0'
multiple: false
supervised: false
allowmanualinstall: true
sharedipad:
mode: allowed
devicechannel: true
userchannel: true
userenrollment:
mode: allowed
macOS:
introduced: '10.13'
multiple: false
devicechannel: true
userchannel: true
requiresdep: false
@@ -12,10 +24,15 @@ payload:
allowmanualinstall: true
userenrollment:
mode: allowed
tvOS:
introduced: '17.0'
multiple: false
supervised: false
allowmanualinstall: true
payloadkeys:
- key: ANY
type: <any>
presence: optional
content: Keys relevant to 802.1x configuration. User enrollment payloads do not
content: Keys relevant to 802.1X configuration. User enrollment payloads do not
support the various proxy keys including ProxyType, ProxyServer, ProxyServerPort,
ProxyUsername, ProxyPassword,, ProxyPACURL and ProxyPACFallbackAllowed.
ProxyUsername, ProxyPassword, ProxyPACURL and ProxyPACFallbackAllowed.
+1
View File
@@ -6,6 +6,7 @@ payload:
supportedOS:
iOS:
introduced: '9.3'
multiple: true
supervised: false
allowmanualinstall: true
sharedipad:
@@ -5,6 +5,7 @@ payload:
supportedOS:
iOS:
introduced: '9.3'
multiple: false
supervised: true
allowmanualinstall: true
sharedipad:
@@ -15,6 +16,7 @@ payload:
mode: forbidden
tvOS:
introduced: '11.0'
multiple: false
supervised: true
allowmanualinstall: true
content: The payload defines a layout of apps, folders, & web clips for the Home
+4 -2
View File
@@ -6,6 +6,7 @@ payload:
macOS:
introduced: '10.9'
deprecated: '10.13'
multiple: false
devicechannel: true
userchannel: true
requiresdep: false
@@ -18,9 +19,10 @@ payloadkeys:
type: <boolean>
presence: optional
default: true
content: If 'false', suppresses profanity.
content: If 'false', suppresses profanity. Use 'forceAssistantProfanityFilter' in
Restrictions instead.
- key: Ironwood Allowed
type: <boolean>
presence: optional
default: true
content: If 'false', disables dictation.
content: If 'false', disables dictation. Use 'allowDictation' in Restrictions instead.
@@ -8,6 +8,7 @@ payload:
introduced: '10.7'
deprecated: '10.14'
removed: '10.14'
multiple: true
devicechannel: false
userchannel: true
requiresdep: false
+2
View File
@@ -6,6 +6,7 @@ payload:
supportedOS:
iOS:
introduced: '4.0'
multiple: true
supervised: false
allowmanualinstall: true
sharedipad:
@@ -16,6 +17,7 @@ payload:
mode: allowed
macOS:
introduced: '10.7'
multiple: true
devicechannel: false
userchannel: true
requiresdep: false
@@ -5,6 +5,7 @@ payload:
supportedOS:
macOS:
introduced: '10.13'
multiple: true
devicechannel: true
userchannel: true
requiresdep: false
@@ -32,4 +33,4 @@ payloadkeys:
type: <boolean>
presence: optional
default: false
content: If true, hide this item in the Users & Groups login items list.
content: If 'true', hide this item in the Users & Groups login items list.
+21 -2
View File
@@ -5,6 +5,7 @@ payload:
supportedOS:
macOS:
introduced: '10.7'
multiple: true
devicechannel: true
userchannel: false
requiresdep: false
@@ -144,7 +145,7 @@ payloadkeys:
type: <boolean>
presence: optional
default: false
content: If 'True', shows the Input Menu in the login window.
content: If 'true', shows the Input Menu in the login window.
- key: DisableFDEAutoLogin
supportedOS:
macOS:
@@ -152,4 +153,22 @@ payloadkeys:
type: <boolean>
presence: optional
default: false
content: If t'rue', disables the automatic login option when using FileVault.
content: If 'true', disables the automatic login option when using FileVault.
- key: AutologinUsername
supportedOS:
macOS:
introduced: '14.0'
allowmanualinstall: false
type: <string>
presence: optional
content: The user short name to set up auto login.
- key: AutologinPassword
supportedOS:
macOS:
introduced: '14.0'
allowmanualinstall: false
type: <string>
presence: optional
content: An optional user password to set up auto login. If this key doesn't exist
but a user name does exist, the system sets up auto login the next time the user
logs in to the client.
+1
View File
@@ -6,6 +6,7 @@ payload:
supportedOS:
macOS:
introduced: '11.0'
multiple: false
devicechannel: true
userchannel: false
requiresdep: false
+8
View File
@@ -5,6 +5,7 @@ payload:
supportedOS:
iOS:
introduced: '4.0'
multiple: true
supervised: false
allowmanualinstall: true
sharedipad:
@@ -15,6 +16,7 @@ payload:
mode: allowed
macOS:
introduced: '10.7'
multiple: true
devicechannel: false
userchannel: true
requiresdep: false
@@ -207,6 +209,8 @@ payloadkeys:
supportedOS:
iOS:
introduced: '10.0'
macOS:
introduced: n/a
type: <boolean>
presence: optional
default: false
@@ -231,6 +235,8 @@ payloadkeys:
iOS:
introduced: '8.0'
deprecated: '10.0'
macOS:
introduced: n/a
type: <boolean>
presence: optional
default: false
@@ -287,6 +293,8 @@ payloadkeys:
supportedOS:
iOS:
introduced: '12.0'
macOS:
introduced: n/a
type: <boolean>
presence: optional
default: false
@@ -4,6 +4,7 @@ payload:
supportedOS:
macOS:
introduced: '10.7'
multiple: false
devicechannel: true
userchannel: true
requiresdep: false
@@ -5,6 +5,7 @@ payload:
supportedOS:
macOS:
introduced: '10.7'
multiple: false
devicechannel: true
userchannel: false
requiresdep: false
+1
View File
@@ -4,6 +4,7 @@ payload:
supportedOS:
macOS:
introduced: '10.7'
multiple: false
devicechannel: true
userchannel: true
requiresdep: false
+35 -8
View File
@@ -5,6 +5,7 @@ payload:
supportedOS:
iOS:
introduced: '4.0'
multiple: false
supervised: false
allowmanualinstall: true
sharedipad:
@@ -15,6 +16,7 @@ payload:
mode: allowed
macOS:
introduced: '10.7'
multiple: false
devicechannel: true
userchannel: false
requiresdep: false
@@ -24,8 +26,14 @@ payload:
mode: allowed
tvOS:
introduced: '6.0'
multiple: false
supervised: false
allowmanualinstall: true
watchOS:
introduced: '10.0'
multiple: false
supervised: true
allowmanualinstall: false
payloadkeys:
- key: IdentityCertificateUUID
title: Identity Certificate UUID
@@ -105,48 +113,61 @@ payloadkeys:
supportedOS:
iOS:
introduced: '13.1'
deprecated: '17.0'
userenrollment:
mode: required
macOS:
introduced: '10.15'
deprecated: '14.0'
userenrollment:
mode: required
tvOS:
introduced: n/a
watchOS:
introduced: n/a
type: <string>
presence: optional
content: The Managed Apple ID of the user. Available in iOS 13.1 and later, and
macOS 10.15 and later. This is only used with the profile-based BYOD enrollment
flow.
macOS 10.15 and later. This is only used with the profile-driven BYOD enrollment
flow, and must not be present in the BYOD and ADDE account-driven enrollment flows.
As of iOS 17 and macOS 14, profile-driven user enrollments are deprecated and
will be removed in a future release.
- key: AssignedManagedAppleID
title: Assigned Managed Apple ID
supportedOS:
iOS:
introduced: '15.0'
macOS:
introduced: n/a
introduced: '14.0'
tvOS:
introduced: n/a
watchOS:
introduced: n/a
type: <string>
presence: optional
content: The Managed Apple ID pre-assigned to the authenticated user. This is only
used with the account-based BYOD enrollment flow. Available in iOS 15 and later.
content: The Managed Apple ID pre-assigned to the authenticated user. This is required
for the BYOD and ADDE account-driven enrollment flows, and must not be present
in other enrollment flows. Available in iOS 15 and macOS 14, and later.
- key: EnrollmentMode
title: Enrollment Mode
supportedOS:
iOS:
introduced: '15.0'
macOS:
introduced: n/a
introduced: '14.0'
tvOS:
introduced: n/a
watchOS:
introduced: n/a
type: <string>
presence: optional
rangelist:
- BYOD
- ADDE
content: The enrollment mode the server indicates must be used when enrolling. This
must be present for account-based BYOD enrollments, but must not be present for
profile-based BYOD enrollments. Available in iOS 15 and later.
key must be present for BYOD and ADDE account-driven enrollments, and must not
be present in the profile-driven user enrollment flow. Available in iOS 15 and
macOS 14, and later.
- key: ServerURLPinningCertificateUUIDs
supportedOS:
iOS:
@@ -201,12 +222,14 @@ payloadkeys:
content: |-
A unique array of strings indicating server capabilities. If the server manages macOS devices or a Shared iPad, this field is mandatory and must contain the value 'com.apple.mdm.per-user-connections', which indicates that the server supports both device and user connections.
Starting with macOS 11, it is also recommended that macOS device enrollment profiles contain the value 'com.apple.mdm.bootstraptoken' to ensure the Bootstrap Token is created and escrowed with the MDM server at enrollment time.
If the server supports the "GetToken" CheckIn message type, then this key must be present and must include "com.apple.mdm.token" as one of its values.
subkeys:
- key: ServerCapabilitiesItems
type: <string>
rangelist:
- com.apple.mdm.per-user-connections
- com.apple.mdm.bootstraptoken
- com.apple.mdm.token
- key: CheckOutWhenRemoved
type: <boolean>
presence: optional
@@ -221,6 +244,8 @@ payloadkeys:
introduced: n/a
tvOS:
introduced: n/a
watchOS:
introduced: n/a
type: <integer>
presence: optional
content: |-
@@ -235,6 +260,8 @@ payloadkeys:
introduced: '11.0'
tvOS:
introduced: n/a
watchOS:
introduced: n/a
type: <boolean>
presence: optional
default: false
@@ -5,6 +5,7 @@ payload:
supportedOS:
iOS:
introduced: '4.0'
multiple: true
supervised: false
allowmanualinstall: true
sharedipad:
@@ -13,6 +14,7 @@ payload:
mode: allowed
macOS:
introduced: '10.7'
multiple: true
devicechannel: true
userchannel: true
requiresdep: false
@@ -20,6 +22,11 @@ payload:
allowmanualinstall: true
userenrollment:
mode: forbidden
watchOS:
introduced: '10.0'
multiple: true
supervised: false
allowmanualinstall: true
payloadkeys:
- key: allowSimple
title: Allow Simple Value
@@ -30,9 +37,9 @@ payloadkeys:
type: <boolean>
presence: optional
default: true
content: If 'false', prevents use of a simple passcode. A simple passcode contains
repeated characters, or increasing or decreasing characters (such as '123' or
'CBA').
content: If 'false', the system prevents use of a simple passcode. A simple passcode
contains repeated characters, or increasing or decreasing characters, such as
'123' or 'CBA'.
- key: forcePIN
title: Require Passcode on Device
supportedOS:
@@ -42,7 +49,7 @@ payloadkeys:
type: <boolean>
presence: optional
default: false
content: If 'true', forces the user to enter a PIN.
content: If 'true', the system forces the user to enter a PIN.
- key: maxFailedAttempts
title: Maximum Number of Failed Attempts
supportedOS:
@@ -56,10 +63,11 @@ payloadkeys:
max: 11
default: 11
content: The number of allowed failed attempts to enter the passcode at the device's
lock screen. After six failed attempts, a time delay is imposed before a passcode
can be entered again. The delay increases with each attempt. In macOS, set 'minutesUntilFailedLoginReset'
to define a delay before the next passcode can be entered. When this number is
exceeded in macOS, the device is locked; in iOS, the device is wiped.
lock screen. After six failed attempts, the system imposes a time delay before
a passcode can be entered again. The delay increases with each attempt. In macOS,
set 'minutesUntilFailedLoginReset' to define a delay before the next passcode
can be entered. When this number is exceeded in macOS, the system locks the device;
in iOS, the system wipes the device.
- key: maxInactivity
title: Auto-Lock
supportedOS:
@@ -71,12 +79,10 @@ payloadkeys:
range:
min: 0
max: 15
content: The maximum number of minutes for which the device can be idle, without
being unlocked by the user, before it gets locked by the system. When this limit
is reached, the device is locked and the passcode must be entered. The user can
edit this setting, but the value cannot exceed the 'maxInactivity' value. In macOS,
this inactivity value is translated to screen-saver settings. The maximum value
for macOS is 60 minutes.
content: |-
The maximum number of minutes for which the device can be idle without the user unlocking it, before the system locks it. When this limit is reached, the system locks the device and the passcode is required to unlock it. The user can edit this setting, but the value can't exceed the 'maxInactivity' value.
In macOS, the system translates this inactivity value to screen-saver settings. The maximum value for macOS is '60'.
Setting this key removes the 'never' option in the Settings UI on user enrolled devices.
- key: maxPINAgeInDays
title: Maximum Passcode Age
supportedOS:
@@ -89,14 +95,16 @@ payloadkeys:
min: 0
max: 730
content: The number of days for which the passcode can remain unchanged. After this
number of days, the user is forced to change the passcode before the device is
unlocked.
number of days, the system forces the user to change the passcode before it unlocks
the device.
- key: minComplexChars
title: Minimum Number of Complex Characters
supportedOS:
iOS:
userenrollment:
mode: ignored
watchOS:
introduced: n/a
type: <integer>
presence: optional
range:
@@ -104,8 +112,8 @@ payloadkeys:
max: 4
default: 0
content: |-
The minimum number of complex characters that a passcode must contain. A complex character is a character other than a number or a letter, such as & % $ #.
This property is ignored for User Enrollments.
The minimum number of complex characters that a passcode needs to contain. A complex character is a character other than a number or a letter, such as '&', '%', '$', and '#'.
The system ignores this property for User Enrollments.
- key: minLength
title: Minimum Passcode Length
supportedOS:
@@ -118,18 +126,20 @@ payloadkeys:
min: 0
max: 16
default: 0
content: The minimum overall length of the passcode. This parameter is independent
of the also optional minComplexChars argument.
content: The minimum overall length of the passcode. This value is independent of
the value for 'minComplexChars'.
- key: requireAlphanumeric
title: Require Alphabetic Value
supportedOS:
iOS:
userenrollment:
mode: ignored
watchOS:
introduced: n/a
type: <boolean>
presence: optional
default: false
content: If 'true', requires alphabetic characters (abcd) instead of only numeric
content: If 'true', the system requires alphabetic characters instead of only numeric
characters.
- key: pinHistory
title: Passcode History
@@ -154,8 +164,9 @@ payloadkeys:
presence: optional
default: 0
content: The maximum grace period, in minutes, to unlock the phone without entering
a passcode. The default is 0, which is no grace period and requires a passcode
immediately. In macOS, this grace period value is translated to screen-saver settings.
a passcode. The default is '0', which is no grace period and requires a passcode
immediately. In macOS, the system translates this grace period value to screen-saver
settings.
- key: minutesUntilFailedLoginReset
supportedOS:
iOS:
@@ -164,10 +175,12 @@ payloadkeys:
introduced: '10.10'
userenrollment:
mode: ignored
watchOS:
introduced: n/a
type: <integer>
presence: optional
content: The number of minutes before the login is reset after the maximum number
of unsuccessful login attempts is reached. This key requires setting 'maxFailedAttempts'.
content: The number of minutes before the system resets the login after the maximum
number of unsuccessful login attempts is reached. This key requires setting 'maxFailedAttempts'.
Available in macOS 10.10 and later.
- key: changeAtNextAuth
supportedOS:
@@ -177,10 +190,45 @@ payloadkeys:
introduced: '10.13'
userenrollment:
mode: ignored
watchOS:
introduced: n/a
type: <boolean>
presence: optional
default: false
content: If 'true', causes a password reset to occur the next time the user tries
to authenticate. If this key is set in a device profile, the setting takes effect
for all users, and admin authentications may fail until the admin user password
is also reset. Available in macOS 10.13 and later.
content: If 'true', the system causes a password reset to occur the next time the
user tries to authenticate. If this key is set in a device profile, the setting
takes effect for all users, and admin authentications may fail until the admin
user password is also reset. Available in macOS 10.13 and later.
- key: customRegex
supportedOS:
iOS:
introduced: n/a
macOS:
introduced: '14.0'
watchOS:
introduced: n/a
type: <dictionary>
presence: optional
content: |-
Specifies a regular expression, and its description, used to enforce password compliance. Use the simpler passcode restrictions whenever possible, and rely on regular expression matching only when necessary. Mistakes in regular expressions can lead to frustrating user experiences, such as unsatisfiable passcode policies, or policy descriptions that don't match the enforced policy.
Available in macOS 14 and later.
subkeys:
- key: passwordContentRegex
type: <string>
presence: required
content: A regular expression string that they system matches against the password
to determine whether it complies with a policy. The regular expression uses
the ICU syntax (<https://unicode-org.github.io/icu/userguide/strings/regexp.html>).
The string must not exceed 2048 characters in length.
- key: passwordContentDescription
type: <dictionary>
presence: optional
content: Contains a dictionary of keys for supported OS language IDs (for example,
“en-US”), and whose values represent a localized description of the policy enforced
by the regular expression. Use the special 'default' key can for languages that
aren't contained in the dictionary.
subkeys:
- key: ANY
type: <string>
presence: optional
content: A localized description.
@@ -5,6 +5,7 @@ payload:
supportedOS:
iOS:
introduced: '9.0'
multiple: false
supervised: false
allowmanualinstall: false
sharedipad:
@@ -5,6 +5,7 @@ payload:
supportedOS:
iOS:
introduced: '9.3'
multiple: false
supervised: true
allowmanualinstall: true
sharedipad:
@@ -15,6 +16,7 @@ payload:
mode: forbidden
macOS:
introduced: '10.15'
multiple: true
devicechannel: true
userchannel: true
requiresdep: false
@@ -7,6 +7,7 @@ payload:
introduced: '9.0'
deprecated: '12.0'
removed: '12.0'
multiple: true
supervised: false
allowmanualinstall: true
sharedipad:
@@ -4,6 +4,7 @@ payload:
supportedOS:
macOS:
introduced: '10.10'
multiple: false
devicechannel: true
userchannel: true
requiresdep: false
@@ -4,6 +4,7 @@ payload:
supportedOS:
macOS:
introduced: '10.12'
multiple: false
devicechannel: true
userchannel: true
requiresdep: false
@@ -5,6 +5,7 @@ payload:
supportedOS:
iOS:
introduced: '4.0'
multiple: false
supervised: true
allowmanualinstall: true
sharedipad:
@@ -13,6 +14,7 @@ payload:
mode: forbidden
macOS:
introduced: '10.7'
multiple: false
devicechannel: true
userchannel: true
requiresdep: false
@@ -22,6 +24,7 @@ payload:
mode: forbidden
tvOS:
introduced: '9.0'
multiple: false
supervised: true
allowmanualinstall: true
payloadkeys:
+17 -8
View File
@@ -5,6 +5,7 @@ payload:
supportedOS:
iOS:
introduced: '6.0'
multiple: false
supervised: true
allowmanualinstall: true
sharedipad:
@@ -15,9 +16,9 @@ payload:
mode: forbidden
macOS:
introduced: '10.9'
multiple: false
devicechannel: true
userchannel: false
supervised: true
requiresdep: false
userapprovedmdm: false
allowmanualinstall: true
@@ -25,6 +26,7 @@ payload:
mode: forbidden
tvOS:
introduced: '6.0'
multiple: false
supervised: true
allowmanualinstall: true
content: PEM-encoded cer
@@ -44,30 +46,37 @@ payloadkeys:
title: Proxy Server
type: <string>
subtype: <hostname>
presence: required
content: The proxy server's network address.
presence: optional
content: The proxy server's network address. This is required if the ProxyType is
set to Manual, and is ignored if the ProxyType is set to Automatic.
- key: ProxyServerPort
title: Proxy Server Port
type: <integer>
presence: required
content: The proxy server's port number.
presence: optional
content: The proxy server's port number. This is required if the ProxyType is set
to Manual, and is ignored if the ProxyType is set to Automatic.
- key: ProxyUsername
title: Proxy Username
type: <string>
presence: optional
content: The user name used to authenticate to the proxy server.
content: The user name used to authenticate to the proxy server. This setting is
only used if the ProxyType is set to Manual, and is ignored if the ProxyType is
set to Automatic.
- key: ProxyPassword
title: Proxy Password
type: <string>
presence: optional
content: The password used to authenticate to the proxy server.
content: The password used to authenticate to the proxy server. This setting is
only used if the ProxyType is set to Manual, and is ignored if the ProxyType is
set to Automatic.
- key: ProxyPACURL
title: Proxy PAC URL
type: <string>
presence: optional
content: The URL of the PAC file that defines the proxy configuration. Starting
in iOS 13 and macOS 10.15, only URLs that begin with 'http://' or 'https://' are
allowed.
allowed. This setting is only used if the ProxyType is set to Automatic, and is
ignored if the ProxyType is set to Manual.
- key: ProxyPACFallbackAllowed
title: Proxy PAC Fallback Allowed
supportedOS:
+115
View File
@@ -0,0 +1,115 @@
title: Relay
description: Use this section to define settings for network relays.
payload:
payloadtype: com.apple.relay.managed
supportedOS:
iOS:
introduced: '17.0'
multiple: true
supervised: false
allowmanualinstall: true
sharedipad:
mode: allowed
devicechannel: true
userchannel: false
userenrollment:
mode: forbidden
macOS:
introduced: '14.0'
multiple: true
devicechannel: true
userchannel: true
requiresdep: false
userapprovedmdm: false
allowmanualinstall: true
userenrollment:
mode: forbidden
payloadkeys:
- key: Relays
title: Relays
type: <array>
presence: required
content: An array of dictionaries that describes one or more relay servers that
can be chained together.
subkeys:
- key: Relay
title: Network Relay
type: <dictionary>
subkeys:
- key: HTTP3RelayURL
title: HTTP/3 Relay URL
type: <string>
presence: optional
content: The URL or URI template (such as defined in RFC 9298) of a relay server
that is reachable using HTTP/3 and supports proxying TCP and UDP using the
CONNECT method. Each relay must have at least one URL, for either HTTP/3 or
HTTP/2, and may support both.
- key: HTTP2RelayURL
title: HTTP/2 Relay URL
type: <string>
presence: optional
content: The URL or URI template (such as defined in RFC 9298) of a relay server
that is reachable using HTTP/2 and supports proxying TCP and UDP using the
CONNECT method. Each relay must have at least one URL, for either HTTP/3 or
HTTP/2, and may support both.
- key: AdditionalHTTPHeaderFields
title: Additional HTTP Header Fields
type: <dictionary>
presence: optional
content: A dictionary of custom HTTP header keys and values to add to each request
to the relay. The dictionary key name represents the HTTP header field name
to use, and the dictionary value is the string to use as the HTTP header field
value.
subkeys:
- key: ANY
type: <string>
presence: required
content: The HTTP header field value for the corresponding header field name.
- key: PayloadCertificateUUID
title: Certificate UUID
type: <string>
presence: optional
format: ^[0-9A-Za-z]{8}-[0-9A-Za-z]{4}-[0-9A-Za-z]{4}-[0-9A-Za-z]{4}-[0-9A-Za-z]{12}$
content: UUID pointing to an identity certificate payload. This identity will
be used to authenticate the user to the relay server.
- key: RawPublicKeys
title: Raw Public Keys
type: <array>
presence: optional
content: An array of raw public keys used to authenticate the server during
a TLS handshake. The server must use one of the keys in the handshake in order
to authenticate. If no keys are specified, default TLS trust evaluation is
used.
subkeys:
- key: RawPublicKeysElement
title: Raw Public Key Element
type: <data>
- key: MatchDomains
title: Match Domains
type: <array>
presence: optional
content: A list of domain strings used to determine which connection should be routed
through the servers contained in Relays. Any connection that matches the domain
exactly or is a subdomain of the listed domain will use the relay servers, unless
they match an excluded domain. If no domains are listed, traffic to all domains,
except those matching an excluded domain, will be routed to the relay servers.
subkeys:
- key: MatchDomainsElement
title: Match Domains Element
type: <string>
- key: ExcludedDomains
title: Excluded Domains
type: <array>
presence: optional
content: A list of domain strings that should not be routed through the servers
contained in Relays. Any connection that matches the domain exactly or is a subdomain
of the listed domain will not use the relay server.
subkeys:
- key: ExcludedDomainsElement
title: Excluded Domains Element
type: <string>
- key: RelayUUID
type: <string>
presence: optional
content: A globally-unique identifier for this relay configuration. This UUID is
used to route managed apps through the servers contained in Relays.
@@ -5,6 +5,7 @@ payload:
supportedOS:
macOS:
introduced: '10.11'
multiple: false
devicechannel: false
userchannel: true
requiresdep: false
+1
View File
@@ -5,6 +5,7 @@ payload:
supportedOS:
macOS:
introduced: '10.11'
multiple: false
devicechannel: true
userchannel: false
requiresdep: false
@@ -5,6 +5,7 @@ payload:
supportedOS:
macOS:
introduced: '10.7'
multiple: false
devicechannel: true
userchannel: true
requiresdep: false
@@ -5,6 +5,7 @@ payload:
supportedOS:
macOS:
introduced: '10.7'
multiple: false
devicechannel: true
userchannel: true
requiresdep: false
@@ -5,6 +5,7 @@ payload:
supportedOS:
macOS:
introduced: '10.13'
multiple: false
devicechannel: true
userchannel: false
requiresdep: false
@@ -6,6 +6,7 @@ payload:
macOS:
introduced: '10.9'
deprecated: '10.13'
multiple: false
devicechannel: true
userchannel: false
requiresdep: false
+25 -10
View File
@@ -6,6 +6,7 @@ payload:
supportedOS:
iOS:
introduced: '16.0'
multiple: true
supervised: false
allowmanualinstall: true
sharedipad:
@@ -16,6 +17,7 @@ payload:
mode: allowed
macOS:
introduced: '13.1'
multiple: true
devicechannel: true
userchannel: true
requiresdep: false
@@ -25,6 +27,12 @@ payload:
mode: allowed
tvOS:
introduced: '16.0'
multiple: true
supervised: false
allowmanualinstall: true
watchOS:
introduced: '9.0'
multiple: true
supervised: false
allowmanualinstall: true
content: Use this payload to specify settings that allow the device to request a
@@ -33,8 +41,8 @@ payload:
it requests an attestation of the key and device properties. Then it communicates
with the ACME server to authenticate the device, provide the attestation, and
request a matching certificate based upon the ClientIdentifier, Subject, SubjectAltName,
KeyUsage, and ExtendedKeyUsage fields. The ACME server issues a certificate and
the device installs it in the keychain. Other payloads can reference the resulting
UsageFlags, and ExtendedKeyUsage fields. The ACME server issues a certificate
and the device installs it in the keychain. Other payloads can reference the resulting
client identity by the payload's PayloadUUID.
payloadkeys:
- key: DirectoryURL
@@ -77,7 +85,7 @@ payloadkeys:
If 'false', the private key isn't bound to the device.
If 'true', the private key is bound to the device. The Secure Enclave generates the key pair, and the private key is cryptographically entangled with a system key. This prevents the system from exporting the private key.
If 'true', 'KeyType' must be 'ECSECPrimeRandom' and 'KeySize' must be 256 or 384.
On macOS, this key is required but must have a value of 'false'.
This key is supported as of macOS 14 on Apple Silicon and Intel devices that have a T2 chip. Older macOS versions or other Mac devices require this key but it must have a value of 'false'.
- key: Subject
title: Subject
type: <array>
@@ -88,16 +96,16 @@ payloadkeys:
[ [ [”C”, “US”] ], [ [”O”, “Apple Inc.”] ], ..., [ [ “1.2.5.3”, “bar” ] ] ]
Dotted numbers can represent OIDs , with shortcuts for country (C), locality (L), state (ST), organization (O), organizational unit (OU), and common name (CN).
subkeys:
- key: SCEPSubjectArrayInnerArray
title: Array Inside SCEP Subject Array
- key: ACMESubjectArrayInnerArray
title: Array Inside ACME Subject Array
type: <array>
subkeys:
- key: SCEPSubjectArrayPair
- key: ACMESubjectArrayPair
title: Subject Array Pair
type: <array>
subkeys:
- key: SCEPSubjectArrayPairItem
title: SCEP Subject Array Pair Item
- key: ACMESubjectArrayPairItem
title: ACME Subject Array Pair Item
type: <string>
repetition:
min: 2
@@ -137,7 +145,7 @@ payloadkeys:
content: |-
This value is a bit field.
* Bit '0x01' indicates digital signature.
* Bit '0x10' indicates key agreement.
* Bit '0x04' indicates encryption.
The device requests this key for the certificate that the ACME server issues. The ACME server may override or ignore this field in the certificate it issues.
- key: ExtendedKeyUsage
title: Extended Key Usage
@@ -152,19 +160,24 @@ payloadkeys:
presence: optional
- key: Attest
title: Attest
supportedOS:
watchOS:
introduced: '10.0'
type: <boolean>
presence: optional
default: false
content: |-
If 'true', the device provides attestations describing the device and the generated key to the ACME server. The server can use the attestations as strong evidence that the key is bound to the device, and that the device has properties listed in the attestation. The server can use that as part of a trust score to decide whether to issue the requested certificate.
When 'Attest' is 'true', 'HardwareBound' must also be 'true'.
On macOS, if this key is present, it must have a value of 'false'.
This key is supported as of macOS 14 on Apple Silicon and Intel devices that have a T2 chip. If this key is specified for older macOS versions or other Mac devices, it must have a value of 'false'.
- key: KeyIsExtractable
supportedOS:
iOS:
introduced: n/a
tvOS:
introduced: n/a
watchOS:
introduced: n/a
type: <boolean>
presence: optional
default: true
@@ -177,6 +190,8 @@ payloadkeys:
introduced: n/a
tvOS:
introduced: n/a
watchOS:
introduced: n/a
type: <boolean>
presence: optional
default: false
@@ -5,6 +5,7 @@ payload:
supportedOS:
macOS:
introduced: '10.12'
multiple: true
devicechannel: false
userchannel: true
requiresdep: false
@@ -5,6 +5,7 @@ payload:
supportedOS:
iOS:
introduced: '14.2'
multiple: true
supervised: false
allowmanualinstall: true
sharedipad:
@@ -5,6 +5,7 @@ payload:
supportedOS:
iOS:
introduced: 12.1.1
multiple: true
supervised: false
allowmanualinstall: true
sharedipad:
@@ -15,6 +16,7 @@ payload:
mode: allowed
macOS:
introduced: 10.14.2
multiple: true
devicechannel: true
userchannel: false
requiresdep: false
@@ -24,10 +26,12 @@ payload:
mode: allowed
tvOS:
introduced: 12.1.1
multiple: true
supervised: false
allowmanualinstall: true
watchOS:
introduced: 5.1.1
multiple: true
supervised: false
allowmanualinstall: true
content: Policies that affect system-wide certificate transparency enforcement.
@@ -5,6 +5,7 @@ payload:
supportedOS:
macOS:
introduced: '10.12'
multiple: true
devicechannel: true
userchannel: false
requiresdep: false
@@ -77,6 +78,7 @@ payloadkeys:
introduced: '12.3'
type: <boolean>
presence: optional
default: true
content: |-
If 'true', allows built-in software to receive incoming connections.
Available in macOS 12.3 and later.
@@ -86,6 +88,7 @@ payloadkeys:
introduced: '12.3'
type: <boolean>
presence: optional
default: true
content: |-
If 'true', allows downloaded signed software to receive incoming connections.
Available in macOS 12.3 and later.
@@ -5,6 +5,7 @@ payload:
supportedOS:
macOS:
introduced: '10.12'
multiple: true
devicechannel: false
userchannel: true
requiresdep: false
+4
View File
@@ -5,6 +5,7 @@ payload:
supportedOS:
iOS:
introduced: '4.0'
multiple: true
supervised: false
allowmanualinstall: true
sharedipad:
@@ -15,6 +16,7 @@ payload:
mode: allowed
macOS:
introduced: '10.7'
multiple: true
devicechannel: true
userchannel: true
requiresdep: false
@@ -24,10 +26,12 @@ payload:
mode: allowed
tvOS:
introduced: '5.0'
multiple: true
supervised: false
allowmanualinstall: true
watchOS:
introduced: '3.0'
multiple: true
allowmanualinstall: true
content: PEM-encoded certificate without private key. May contain root certificates.
payloadkeys:
@@ -5,6 +5,7 @@ payload:
supportedOS:
iOS:
introduced: '4.0'
multiple: true
supervised: false
allowmanualinstall: true
sharedipad:
@@ -15,6 +16,7 @@ payload:
mode: allowed
macOS:
introduced: '10.7'
multiple: true
devicechannel: true
userchannel: true
requiresdep: false
@@ -24,10 +26,12 @@ payload:
mode: allowed
tvOS:
introduced: '5.0'
multiple: true
supervised: false
allowmanualinstall: true
watchOS:
introduced: '3.0'
multiple: true
allowmanualinstall: true
content: DER-encoded certificate without private key. May contain root certificates.
payloadkeys:
+5 -1
View File
@@ -5,6 +5,7 @@ payload:
supportedOS:
iOS:
introduced: '4.0'
multiple: true
supervised: false
allowmanualinstall: true
sharedipad:
@@ -15,6 +16,7 @@ payload:
mode: allowed
macOS:
introduced: '10.7'
multiple: true
devicechannel: true
userchannel: true
requiresdep: false
@@ -24,10 +26,12 @@ payload:
mode: allowed
tvOS:
introduced: '5.0'
multiple: true
supervised: false
allowmanualinstall: true
watchOS:
introduced: '3.0'
multiple: true
allowmanualinstall: true
content: Password-protected identity certificate. Only one certificate may be included.
payloadkeys:
@@ -77,4 +81,4 @@ payloadkeys:
type: <boolean>
presence: optional
default: true
content: If false, does not tag the private key data as extractable in the keychain.
content: If 'false', does not tag the private key data as extractable in the keychain.
@@ -5,6 +5,7 @@ payload:
supportedOS:
iOS:
introduced: '4.0'
multiple: true
supervised: false
allowmanualinstall: true
sharedipad:
@@ -15,6 +16,7 @@ payload:
mode: allowed
macOS:
introduced: '10.7'
multiple: true
devicechannel: true
userchannel: true
requiresdep: false
@@ -24,10 +26,12 @@ payload:
mode: allowed
tvOS:
introduced: '5.0'
multiple: true
supervised: false
allowmanualinstall: true
watchOS:
introduced: '3.0'
multiple: true
allowmanualinstall: true
content: Alias for com.apple.security.pkcs1.
payloadkeys:
+8 -2
View File
@@ -6,6 +6,7 @@ payload:
supportedOS:
iOS:
introduced: '4.0'
multiple: true
supervised: false
allowmanualinstall: true
sharedipad:
@@ -16,6 +17,7 @@ payload:
mode: allowed
macOS:
introduced: '10.7'
multiple: true
devicechannel: true
userchannel: true
requiresdep: false
@@ -25,6 +27,12 @@ payload:
mode: allowed
tvOS:
introduced: '6.0'
multiple: true
supervised: false
allowmanualinstall: true
watchOS:
introduced: '3.0'
multiple: true
supervised: false
allowmanualinstall: true
payloadkeys:
@@ -106,10 +114,8 @@ payloadkeys:
default: 0
content: |-
A bitmask indicating the use of the key.
* 1: Signing
* 4: Encryption
Some certificate authorities, such as Windows CA, support only encryption or signing, but not both at the same time.
- key: CAFingerprint
title: Fingerprint

Some files were not shown because too many files have changed in this diff Show More